HIPAA Privacy Policies: What Your Organization Must Include
In 2023, OCR settled with a dental practice in New England for $350,000 after investigators discovered the organization had no written policies governing the
A collection of 202 posts
In 2023, OCR settled with a dental practice in New England for $350,000 after investigators discovered the organization had no written policies governing the
In 2023, a dental practice in New England paid $50,000 to settle an OCR investigation after a workforce member posted a patient's
In February 2024, OCR announced a $4.75 million settlement with Montefiore Medical Center after a former employee accessed and sold protected health information (PHI)
In March 2024, OCR settled with a healthcare provider for $950,000 after an investigation revealed the organization had failed to conduct a risk analysis
In February 2023, OCR settled with a healthcare provider for $1.25 million after determining the organization had never conducted a comprehensive risk analysis — despite
In 2023, OCR settled with a dental practice in New England for $50,000 — not because of a sophisticated cyberattack, but because the organization couldn&
In 2023, OCR settled with a Louisiana medical group for $480,000 after an investigation revealed — among other failures — that the organization had never implemented
In 2023, OCR settled with a Florida dental practice for $30,000 after an investigation revealed that multiple workforce members had never received HIPAA training
In 2024, a regional pharmacy chain paid $1.5 million to settle allegations with the HHS Office for Civil Rights after workforce members improperly accessed
When OCR settled with a Florida dental practice for $62,500 in 2023, the root cause wasn't a sophisticated cyberattack or a rogue
In 2023, OCR settled with a Louisiana medical group for $480,000 after a breach investigation revealed the organization had never implemented a workforce training
In 2023, OCR settled with a dental practice in New England for $23,000 after an investigation revealed that not a single member of the
Join healthcare organizations that trust HIPAA Certify for their workforce training and compliance tracking.